Draft — not yet reviewed by a solicitor. This describes the processing this software actually does, in the shape UK GDPR Article 28 requires of an agreement between a controller and a processor. The bracketed operator details, and the international-transfer position below, need confirming before this is final.
Data Processing Agreement
Draft — last updated 23 September 2026.
The parties
The dealership using WhizzTrack is the controller of its customers’ personal data — it decides who to sell to, what to record about them, and why. [Operator legal name — to be added] is the processor: it stores and processes that data only on the dealership’s instructions, given by using the software. This agreement applies for as long as a dealership holds an account.
Subject matter, duration and purpose
Processing customer records so a dealership can run its stock book: recording a sale, booking an appointment, issuing an invoice, and keeping the financial record HMRC requires. It lasts for as long as the dealership’s account is open, and for sale and invoice records specifically, six years from the end of the financial year of the sale regardless of account status, after which the buyer’s personal details are removed automatically (at most seven years after their last dealings) — the same retention already described in the Privacy Policy.
Whose data, and what kind
Data subjects: a dealership’s customers (people who have bought, viewed, or enquired about a car), and its own staff.
Categories of data: name, address, phone number, email, marketing preference; vehicle and sale details tied to them (price, deposit, whether finance was used and with which lender — never a credit score, application, or check, since this software does not run one); and, for staff, a hashed password and role. No special category data (health, ethnicity, and the rest of UK GDPR Article 9) is deliberately collected by any part of this software.
Sub-processors
The same ones named in the Privacy Policy, and only these unless this page is updated first:
- Fly.io — hosts the application and its database, in the UK.
- Anthropic — reads an uploaded HPI check or similar document, only for dealerships that have switched this on. This is a transfer outside the UK — see below.
- DVLA / DVSA — UK government services a dealership can optionally send a registration to for a basic vehicle record or MOT history.
- Resend — sends the app’s own emails to dealership staff (verification, password resets, the MOT reminder digest). No customer records are sent through it. A US company — see below.
- Sentry — receives crash reports, configured to carry no IP address, cookies, headers, request bodies or database contents. A US company — see below.
- Stripe — only where a dealership connects its own Stripe account to take card deposits: the customer’s email, the car and the amount are passed to that account to set the payment up. The payment itself is between the customer, the dealership and Stripe. A US company — see below.
- Backup storage — holds a nightly backup, encrypted before it leaves Fly.io so the provider holds only ciphertext; 30 days of database copies are kept. [Operator to name the storage company and its location; an EU or UK location avoids a further transfer.]
International transfers
Anthropic, Resend, Sentry and Stripe are US companies. A document sent to Anthropic for reading (only whatever text is on the vehicle document itself), a staff member’s email address sent through Resend, and a crash report sent to Sentry are each a transfer of personal data outside the UK, and each needs a lawful transfer mechanism (the UK International Data Transfer Addendum, most likely) confirmed and named here before this is final. [Operator to confirm with each company’s own data processing terms and add the mechanism relied on.]
What the processor does
- Processes personal data only on the dealership’s documented instructions.
- Keeps every dealership’s data apart from every other’s — enforced in the software itself, not left to a query written carefully enough each time.
- Applies the security measures in the Privacy Policy: hashed passwords, role-based access, TLS in transit, login lockout after repeated wrong attempts, optional two-step sign-in, a two-year log of who opened each customer’s record, and encrypted off-site backups.
- Helps the dealership answer a data subject’s request to see, correct or erase their details — the software already gives a dealership an erase function for exactly this.
- Tells the dealership about a personal data breach without undue delay.
- Deletes or returns personal data when an account closes, except what the law requires to be kept — the same six-year financial record described above.
- Uses no new sub-processor without updating this page first, and gives the dealership the chance to object.
Liability
[Operator to add, with a solicitor: liability and indemnity terms consistent with the Terms of Service, and any audit rights a dealership is given under this agreement.]